CyberSecurity News
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
AI summary
Cybersecurity researchers have revealed a new phishing toolkit called NovaCookies, which is used to capture Microsoft 365 authenticated sessions. This adversary-in-the-middle toolkit acts as a proxy to redirect Microsoft 365 sign-ins. The NovaCookies service is subscription-based, costing $320 per month, and is described as a phishing platform. It abuses legitimate Docusign notifications to steal sessions. The toolkit is designed to intercept and capture authenticated sessions, allowing attackers to gain access to Microsoft 365 accounts.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

